Cyber Designs Members’ Hub — member-account privacy policy
Last updated: 8 October 2026

1. Who we are

Cyber Designs provides a free Members’ Hub with articles and newsletters about supported housing regulation, principle-centred leadership and effective management. This policy explains how we use personal information when you visit the Hub, register, use your account or contact us about membership. It covers members.cyberdesigns.uk; other services and our main website may have separate privacy information.

The controller is Mika Saha, trading as Cyber Designs (sole trader).
Business correspondence address: 40 Church Road, Bedford, MK44 3PU.
Email: members@cyberdesigns.uk.

2. Information we collect

We collect your username, email address, password credentials and any optional profile details you provide, such as your name. Passwords are stored in a hashed form, rather than as readable passwords. We also hold account information such as registration date, membership level, activation status and verification or password-reset information.

Our website and hosting services may record technical information, including IP addresses, browser and device information, pages requested, access times and errors, to operate and protect the service. If you contact us, we keep your message and the information needed to respond.

Your email address and login credentials are needed to create and verify an account and provide access to protected content. There is no legal obligation to join. Membership is free and we do not collect payment-card details for it. Please do not send passwords or identifiable information about residents, service users or staff in membership enquiries.

3. How and why we use information

We use account information to create and administer your membership, verify your email address, authenticate sign-ins, provide protected content, manage profile changes and password recovery, and send essential account messages. We use relevant technical information to maintain the website, investigate faults, prevent misuse and protect accounts. We use correspondence to answer questions and resolve complaints.

Our lawful basis for these activities is legitimate interests: providing the free service you have requested, managing our member relationships, and keeping the website reliable and secure. We consider whether processing is necessary and balance these interests against your rights and reasonable expectations. Where a specific legal duty requires processing, we rely on legal obligation. Any optional email marketing would rely on separate consent.

We do not use your information for solely automated decisions that have legal or similarly significant effects on you. Email activation is a routine account-security step.

4. Account emails and newsletters

Registration allows us to send essential messages such as activation emails, password resets and important service or security notices. Newsletters and articles published inside the Hub are available to verified members. Registering does not subscribe you to marketing emails.

If we offer an optional email newsletter, we will explain it and ask you to opt in separately. You will be able to withdraw that consent using the unsubscribe facility or by emailing us. Withdrawal will not affect earlier lawful processing or your ability to receive essential account messages.

5. Who can access information

Access is limited to authorised administration and providers who need information to deliver or support the service. We use IONOS for WordPress hosting and membership email. The site uses WordPress, Simple Membership and WP Mail SMTP to manage the website, member accounts and account-email delivery. Our hosting provider processes information under its data-processing terms.

We may share relevant information with professional advisers or public authorities when necessary to meet a legal obligation, address a security incident or establish, exercise or defend legal claims. We do not sell member information or publish a member directory.

6. Processing locations and international transfers

Cyber Designs administers the Hub from the United Kingdom. Hosting, email and supporting infrastructure are provided by IONOS and its service providers; processing locations depend on the services involved. We do not promise that all information remains exclusively in the UK.

Where personal information is transferred outside the UK to a destination without applicable UK adequacy regulations, appropriate safeguards are required, such as approved contractual protections, together with any necessary additional measures. Contact us at members@cyberdesigns.uk for information about the arrangements relevant to your data and how to obtain details of applicable safeguards.

7. How long we keep information

We keep information only for as long as it is needed for the purposes described here. Our account-retention schedule is:

Active accounts: while membership remains in use. We review accounts after 24 months of inactivity and aim to give 30 days’ notice before closing an inactive account.
Unverified registrations: delete after 30 days unless an activation or support issue is being resolved.
Closed accounts: remove account information from the live membership system within 30 days, subject to the limited exceptions below.
Membership-support correspondence: normally retain for 12 months after an enquiry is resolved.

Technical and security records are kept for the period needed to operate the service and investigate faults or abuse, taking account of provider retention settings and any ongoing incident. Backup copies may remain after deletion from the live site until they expire through the provider’s backup cycle. IONOS’s standard WordPress recovery service provides daily backups for up to the previous seven days; this does not describe every email or infrastructure record. Backups are used for recovery, and relevant deletion requests must be reapplied if data is restored.

We may retain limited information for longer where necessary for a legal duty, unresolved complaint, security investigation or legal claim. We limit access and review whether continued retention is necessary. If optional email marketing is introduced, we will keep appropriate consent records and minimal suppression information to respect unsubscribe requests.

8. Cookies and security

The Hub uses cookies needed for sign-in, session management, security and access to protected content. Simple Membership uses cookies such as swpm_session, swpm_in_use, wp_swpm_in_use and simple_wp_membership_sec_* to maintain sessions and recognise authenticated members. Cookie names and expiry can vary with the software version and your sign-in choices. Session cookies end with the browser session; choosing “Remember Me” can keep authentication for approximately two weeks.

You can clear or block cookies in your browser, although doing so may prevent sign-in or protected content from working. Avoid “Remember Me” on shared devices and sign out after use. Any optional tracking or third-party features requiring consent must be explained and offered separately before they are enabled. Links to external websites take you to services with their own privacy information.

We use HTTPS and restrict administrative access. Please choose a strong, unique password and tell us promptly if you suspect unauthorised account access. No online system can be guaranteed completely secure.

9. Your rights and account closure

You can update available profile details through your member profile. To close your account or exercise a data-protection right, email members@cyberdesigns.uk. You may have rights to access your information, correct inaccuracies, request erasure, restrict processing and, where the legal conditions apply, receive or transfer information in a portable format. These rights are subject to applicable conditions and exceptions.

You can object to processing based on legitimate interests for reasons relating to your particular situation. We will stop that processing unless we have compelling legitimate grounds that override your interests, rights and freedoms, or need it for legal claims. You have an absolute right to object to direct marketing.

We normally respond within one month and without a fee. Where the law permits an extension or a fee, we will explain why. We may ask for proportionate information to verify your identity, but will never ask you to send your password.

10. Questions and complaints

Please contact members@cyberdesigns.uk if you have a concern about how we use your information. We will investigate and explain our response. You also have the right to complain to the UK Information Commissioner’s Office: ico.org.uk/make-a-complaint/.

11. Changes to this policy

We may update this policy as the Hub or our practices change. The date above shows the latest revision. We will draw significant changes to members’ attention through the Hub or an appropriate account-service notice.